Sploitus

Exploit Code

MARKDOWN61 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-RASTA-MOUSE-WATSON
# Watson

Watson 是一个 .NET 工具,用于枚举缺失的 KB 并建议权限提升漏洞的利用。

## 支持的版本

  * Windows 10 1507, 1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004
  * Server 2016 & 2019



## 使用方法

root@kitploit:~
    
    
    C:\> Watson.exe
      __    __      _
     / / /\ \ \__ _| |_ ___  ___  _ __
     \ \/  \/ / _` | __/ __|/ _ \| '_ \
      \  /\  / (_| | |_\__ \ (_) | | | |
       \/  \/ \__,_|\__|___/\___/|_| |_|
    
                               v2.0
    
                       @_RastaMouse
    
     [*] OS Build Number: 14393
     [*] Enumerating installed KBs...
    
     [!] CVE-2019-0836 : VULNERABLE
      [>] https://exploit-db.com/exploits/46718
      [>] https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/
    
     [!] CVE-2019-0841 : VULNERABLE
      [>] https://github.com/rogue-kdc/CVE-2019-0841
      [>] https://rastamouse.me/tags/cve-2019-0841/
    
     [!] CVE-2019-1064 : VULNERABLE
      [>] https://www.rythmstick.net/posts/cve-2019-1064/
    
     [!] CVE-2019-1130 : VULNERABLE
      [>] https://github.com/S3cur3Th1sSh1t/SharpByeBear
    
     [!] CVE-2019-1253 : VULNERABLE
      [>] https://github.com/padovah4ck/CVE-2019-1253
    
     [!] CVE-2019-1315 : VULNERABLE
      [>] https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html
    
     [*] Finished. Found 6 potential vulnerabilities.
    

## 问题

  * 我尝试在每个补丁星期二后更新 Watson,但如果有潜在误报,请检查 Windows 更新目录 中的最新取代信息。如果仍然认为有错误,请使用 `Bug` 标签提交问题。

  * 如果有特定的漏洞你想在 Watson 中看到但尚未包含,请使用 `Vulnerability Request` 标签提交问题,并附上 CVE 编号。

  * 如果你知道 Watson 中任何漏洞的好的利用代码,请使用 `Exploit Suggestion` 标签提交问题,并提供利用代码的 URL。